Published: Monday, 31 August 2026 · Pocket Bitcoin
On 21 August we published information about the security incident at Pocket Bitcoin. We said then that we would contact customers personally if more than their support correspondence was affected. Those messages went out today.
If you did not receive a personal email from us today, the information in our first blog post still applies to you.
What we have found#
As a regulated company, we are required to verify identity and, for some transactions, the source of funds before a purchase or sale can go ahead. Part of that involves correspondence with the partner bank that processes a payment. Depending on the case it ranges from a name to identity and source of funds documentation. Some of that correspondence was held in our support system, which was among the data affected by the incident.
Our investigation has confirmed that 291 customers are affected in this way. What the correspondence contained differs from case to case: across the group it includes names, postal addresses, bitcoin addresses used for transactions, copies of identity documents and source of funds documentation, in varying combinations, and for most people only some of these. This part of our analysis is complete, and everyone concerned received a personal email from us today setting out exactly what applies to them.
What was affected: more details#
Our first post listed three things as “not affected”: bitcoin addresses, the customer database including KYC data, and transaction history. That was worded broadly. The distinction that matters is between our systems and the data itself: none of those systems were compromised, and that still holds, but data of those kinds was present in the correspondence that was exposed.
Your bitcoin were not at risk at any point. A bitcoin address is not access to funds, it is public information on the blockchain, and moving bitcoin requires private keys, which never leave your device. What the exposure changes is that an address can be linked to a name, and for some customers to a postal address and an amount.
Whether the data has been used#
As things stand, we have no indication that any of the affected information has been misused. That reflects what we can see today rather than a guarantee.
Am I affected?#
If you are one of the 291, you received a personal email from us today, listing exactly what was affected in your case. If you did not receive such an email, nothing beyond what we described on 21 August applies to you, and you do not need to ask us.
What we are doing#
- Every affected customer was contacted directly and personally today.
- The incident has been reported to the Swiss Federal Data Protection and Information Commissioner (FDPIC), and we have filed a police report.
- The forensic investigation is concluded.
- We have already put a number of measures in place and are working on further improvements to how this kind of information is handled and transmitted. We will share more over the next few weeks.
What matters most right now#
Because details from support correspondence were copied, a message referring to this incident can look more convincing than an ordinary one. If an email, call or message asks you to act quickly or to “verify” something, go to the organisation’s official channel yourself rather than using the links or numbers it provides. And Pocket Bitcoin will never ask for your seed phrase.
What happens next#
Any further updates will be posted here. We know an incident like this affects the trust you have placed in us, and to those whose data was exposed, we are sincerely sorry.
The Pocket Bitcoin Team
Frequently asked questions#
How does this fit with what you wrote on 21 August?#
On 21 August we shared what we knew at that early stage and said we would follow up as the investigation progressed. This update is that follow-up. It has since become clear that data held in the correspondence forwarded to our partner banks was affected for 291 customers, including, for some, their KYC data and/or a bitcoin address used for their transaction. Our systems themselves (customer database with KYC data, transaction database) were not compromised; the data was exposed through that copied correspondence. To keep both posts consistent, we have added dated notes to the first one.
Why did you have these documents in the first place?#
As a regulated company, we are required to verify identity and, for some transactions, the source of funds before a purchase or sale can go ahead.
As part of the compliance process we are legally required to follow, we forward certain information to the partner bank that processes a payment. That correspondence was held in our support system, which was among the data affected by the incident. We are reviewing and improving how this kind of information is handled.
Are my bitcoin affected?#
No. Pocket Bitcoin is non-custodial. Your private keys never leave your device, and we never have access to your funds.
Can someone see how much bitcoin I own, and should I move it?#
If your address was exposed, someone holding it can look up the balance and history tied to that address on the blockchain, which is public by design; what is new is that it can be connected to your name. Moving funds does not undo what is already on the blockchain, but it separates your future activity from the exposed address. Either way, nobody can move your bitcoin with the information that was exposed.
What about amounts? You said purchase and sale data was stored separately.#
Our transaction database was not compromised. But where source of funds documentation or correspondence about a payment was affected, amounts were often part of it. For everyone outside this group, nothing about purchase or sale data was affected.
Will there be more cases?#
No. The analysis of the correspondence forwarded to partner banks is complete, and everyone in that group was contacted on 30 August.
Is my future communication with Pocket secure?#
Yes. The vulnerability behind this incident has been closed and we have added further safeguards since, so any email or chat message you send us from now on is handled through our secured systems and is not affected by this incident. Buying and selling are unaffected and work as normal.
Can I ask you to delete my documents?#
Partly. We are legally required to retain certain compliance records for a defined period and cannot delete them within that time. Anything beyond that, write to us and we will check what applies to your account.
Who do I contact with questions?#
If you received a personal email from us, reply to it directly. Our phone lines are busier than usual at the moment, so email is usually faster.